Complies
HIPAA · 164.312

HIPAA compliance software that keeps PHI safeguards tracked and evidenced

If your product touches PHI, HIPAA applies the day your first BAA is signed. Complies tracks the administrative, physical, and technical safeguards as owned obligations, not a binder.

See pricing

HIPAA compliance software tracks the safeguards the law requires around protected health information: Complies maps the Security Rule's administrative, physical, and technical safeguards to your actual controls, keeps business associate agreements signed and current, and collects the evidence that proves the safeguards operate. HIPAA is three rules working together: the Privacy Rule governs how PHI is used and disclosed, the Security Rule (164.308, 164.310, 164.312) demands documented safeguards for electronic PHI starting with a risk analysis, and the Breach Notification Rule requires notifying affected individuals, and HHS, when unsecured PHI is breached. For a healthtech startup, that means signed BAAs with every vendor touching PHI, access controls and audit logging on systems holding it, encryption, workforce training, and written policies. Complies turns each safeguard into an obligation with an owner and a due date, pulls technical evidence from AWS, Okta, and Google Workspace, and drafts policy starting points your team approves. There is no official HIPAA certification, which makes a defensible, documented posture the real goal. HIPAA safeguards overlap heavily with SOC 2 and ISO 27001, so work done there pre-fills your HIPAA map, and Growth at $199 a month includes the cross-mapping.

Complies handles it with policy management software and compliance evidence collection, with every control cross-mapped to the other frameworks you run.

HIPAA DEMANDS

What HIPAA asks of you, in plain language

CodeWhat it demandsHow Complies helps
164.308(a)(1) Conduct and document a risk analysis covering all ePHI The risk register generates the risk analysis HHS asks for first in any investigation: threats, likelihood, impact, and treatment, each with an owner and a review date.
164.312(a) Control technical access to systems that hold ePHI Maps SSO, IAM, and unique user IDs to the access control standard, schedules access reviews, and flags shared or orphaned accounts on PHI systems.
164.312(b) Record and examine activity in systems containing ePHI Collects audit logging configuration and log review evidence from AWS on a schedule, so the audit controls standard proves itself continuously.
164.308(b) Hold business associate agreements with every vendor touching PHI Tracks which vendors receive PHI, stores each signed BAA as evidence with a renewal date, and flags new integrations that lack one.
164.404 Notify affected individuals of breaches of unsecured PHI Keeps the breach response plan, notification templates, and HHS reporting steps approved in advance, and logs incident timelines as evidence of the process.
CROSS-MAP

Collect once, comply many times

The Security Rule is mostly the same engineering work the other frameworks ask for: 164.312(a) access control matches SOC 2 CC6.1, ISO 27001 A.5.15, and GDPR Art. 32; the 164.308(a)(1) risk analysis matches SOC 2 CC3.2 and ISO Clause 6.1.2; audit logging matches PCI DSS Req. 10. What HIPAA adds is PHI-specific: BAAs, minimum necessary use, and breach notification to individuals and HHS. Complies maps shared controls once, marks them satisfied across frameworks, and isolates the genuinely HIPAA-only work, so a SOC 2-ready healthtech team sees most of its HIPAA map pre-filled.

Control areaHIPAAAlso satisfies
Access control 164.312(a) SOC 2 CC6.1 · ISO A.5.15 · GDPR Art. 32 · PCI Req. 7
Risk analysis 164.308(a)(1) SOC 2 CC3.2 · ISO Clause 6.1.2 · PCI Req. 12.3
Audit logging 164.312(b) SOC 2 CC7.2 · ISO A.8.15 · PCI Req. 10
Vendor agreements 164.308(b) SOC 2 CC9.2 · ISO A.5.19 · GDPR Art. 28

See the full crosswalk on the control mapping software page.

THE PATH

Getting HIPAA ready with Complies

01

Map where PHI lives and connect your stack

Connect AWS, Okta, and Google Workspace, mark which systems store or transmit ePHI, and let Complies build the safeguard map across 164.308, 164.310, and 164.312.

02

Run the risk analysis and close the gaps

Work the risk register into the documented risk analysis HHS expects, sign missing BAAs, and approve the AI-drafted policies and training obligations Complies assigns to owners.

03

Keep safeguards evidenced, not just written

Access reviews, log checks, training refreshers, and BAA renewals land on the calendar with owners. The readiness score shows your defensible posture, and the export pack backs it up.

Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.

QUESTIONS

HIPAA questions, answered

No, and neither does anyone else: HHS offers no official HIPAA certification, so any badge claiming it is marketing. Complies assists with compliance workflows: it is not legal advice, and it does not certify you or guarantee regulatory outcomes. Your auditor and regulators decide; Complies gets you ready, with a documented risk analysis, tracked safeguards, and evidence that they operate.

Almost certainly not; you are most likely a business associate, a vendor that creates, receives, or maintains PHI for a covered entity. That still puts the Security Rule and Breach Notification Rule on you directly, and every hospital deal will require a signed BAA. Complies tracks your obligations as a business associate, including the BAAs you in turn need from your own subcontractors.

Encryption is an addressable specification, not optional but risk-driven: you implement it where reasonable and appropriate, or document why an alternative works. In practice, encrypting ePHI in transit and at rest is the expected answer for a cloud product, and it also makes breached data "secured", which changes your notification duties. Complies collects your encryption settings from AWS as recurring evidence.

Very well. Access control, audit logging, risk analysis, and incident response are shared between the Security Rule and SOC 2 CC-series criteria, so controls you built for SOC 2 pre-fill the HIPAA map in Complies. What remains is PHI-specific: BAAs, minimum necessary policies, training, and breach notification. Healthtech buyers commonly ask for both, and one control library serves both audits.

Start your HIPAA readiness today

Growth includes every framework, cross-mapped, at $199 a month.